logo

Critical Oracle WebLogic Flaw Under Active Exploitation

ID: aeec11a2-65b5-579b-850f-251a8414aba9

STIX ID: report--aeec11a2-65b5-579b-850f-251a8414aba9

Feed Name: ThreatCluster

Threat Score
92/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

...
...

CISA added CVE-2026-21962—a critical (CVSS 10.0) vulnerability in Oracle HTTP Server and WebLogic Server Proxy Plug-in—to its Known Exploited Vulnerabilities catalog after observed active exploitation; the flaw allows unauthenticated attackers to gain full access via manipulated URIs, proof-of-concept code is public, and agencies are being ordered to patch within three days and consider exposed systems compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.